Personal Data Processing Agreement (Data Processor)
A KVKK-compliant data processing agreement annex (DPA) governing the processing of end-customers' personal data, under which BotFront acts as the data processor and the customer firm as the data controller.
Effective date: June 16, 2026
1. Parties, Subject Matter of the Agreement, and Allocation of Roles
This Agreement is entered into by and between, on the one part, Lumio Studio, which operates the BotFront platform (e-mail: contact@lumiostudio.co) (hereinafter referred to as "BotFront" or the "Data Processor"), and, on the other part, the customer firm that receives services through the BotFront platform and transfers its own end-customers' personal data to the platform (hereinafter referred to as the "Firm" or the "Data Controller").
botcu is a software (SaaS) provider that integrates Shopify or PlatinMarket stores together with a Meta WhatsApp Business number to offer the Firm's end-customers stock and order assistance over WhatsApp. This Agreement governs solely the processing of the end-customers' personal data defined below under the heading "Categories of Personal Data Processed and Groups of Data Subjects".
- Data Controller
- The Firm, being the party that determines the purposes and means of processing the end-customers' personal data. Fulfilling the duty to inform under the KVKK and ensuring the existence of lawful processing conditions (explicit consent or other legal grounds set out in the Law) are the sole responsibility of the Firm.
- Data Processor
- botcu, which processes the end-customers' personal data on behalf of and for the account of the Firm acting as Data Controller, in accordance with the Firm's written and documented instructions.
- Data Subject
- The end-customer whose personal data is processed (the natural-person recipient or customer with whom the Firm communicates over the WhatsApp channel).
- Sub-Processor
- The third-party subcontractors or service providers whose services BotFront engages in order to carry out the data processing activities under this Agreement (Article 7).
Important Note: There are two separate data flows within the platform: (1) With respect to the Firm's own corporate/authorized data (login e-mail, subscription/billing information, integration credentials, etc.), BotFront acts as the DATA CONTROLLER, and these processes are subject to a separate Privacy Policy and Information Notice. (2) With respect to the end-customers' data, however, the Firm acts as the DATA CONTROLLER and BotFront as the DATA PROCESSOR. This Agreement covers ONLY this second data flow.
2. Scope, Duration, Nature, and Purpose of the Data Processing Activity
- Subject Matter and Nature of the Processing
- Receiving messages arriving from end-customers via the WhatsApp channel, analyzing them for the purpose of intent classification, responding to stock/order queries, and retaining the conversation history. The data processing activity covers the operations of collection, recording, storage, retention, classification, use, and transfer.
- Purpose of the Processing
- Providing the Firm's end-customers with an automated stock and order assistance service over WhatsApp and performing intent classification so that messages can be answered correctly.
- Duration of the Processing
- The data processing activity continues for as long as the main service/subscription agreement between the Firm and BotFront remains in force. Upon termination of the main agreement, the processes for the deletion, destruction, or return of the personal data are carried out in accordance with Article 8.
botcu processes the end-customers' personal data solely for the purpose of providing services to the Firm; it may not use such data for its own commercial purposes, sell or transfer it to third parties, or process it in any manner whatsoever beyond the purposes defined in this Agreement.
3. Categories of Personal Data Processed and Groups of Data Subjects
Group of Data Subjects: The Firm's end-customers (natural persons) with whom it communicates over the WhatsApp channel. The categories of personal data processed are limited to the Firm's instructions and the message content shared by the end-customer, as follows:
- Contact Data: WhatsApp phone number and, if any, the profile name.
- Customer Transaction and Support Data: Message content, order/request information, product and stock queries.
- Conversation Records: Conversation sessions (ConversationSession), chat messages (ChatMessage), and processed message records (ProcessedMessage).
The data stored in BotFront's PostgreSQL database consists of product information, an append-only stock ledger, conversation sessions, chat messages, processed message records, and derived tenant configuration snapshots. Each query is logically segregated on a per-tenant basis, and sensitive access keys and secrets are kept solely in environment variables.
The Firm is obliged not to transfer to the system any special categories of personal data that require explicit consent or a specific legal ground, nor any other data that the bot has not been instructed to process. BotFront provides its services on the assumption that only the data categories specified above will be transferred to the system.
4. Obligations of the Data Processor (BotFront)
In its capacity as data processor, BotFront undertakes to comply with the following obligations pursuant to the KVKK and related legislation:
- Adherence to documented instructions
- It processes the end-customers' personal data solely in accordance with the written and documented instructions provided by the Firm within the scope of this Agreement and the main service agreement. Should it determine, or form the opinion, that a given instruction is contrary to data protection legislation, it shall immediately notify the Firm.
- Confidentiality
- It ensures that its personnel who are authorized to access personal data are bound by a written confidentiality undertaking; it keeps such data confidential throughout the term of the Agreement and indefinitely after the Agreement terminates.
- Security (KVKK Art. 12)
- It takes appropriate technical and administrative measures to prevent the unlawful processing of personal data and unauthorized access to such data, and to ensure the preservation of the data (per-tenant logical segregation, keeping secrets in environment variables, strict access control, and preserving data integrity by means of an append-only ledger structure). The parties' respective responsibilities for taking the security measures required under KVKK Art. 12 are reserved.
- Breach notification
- From the moment it becomes aware that the processed personal data has been obtained by others through unlawful means (a data breach), it notifies the Firm without delay and within 72 hours at the latest. In this notification, it provides information about the nature of the breach, the affected data and groups of data subjects, and the measures taken/to be taken. The obligation to notify the Personal Data Protection Board and the data subjects rests, in its capacity as data controller, solely with the Firm; BotFront provides the information and support necessary for the management of this process.
- Assistance with data subject requests
- It does not directly respond to requests received from data subjects under KVKK Art. 11 (access, rectification, deletion, destruction, etc.); it forwards such requests to the Firm without delay. It provides the technical support necessary for the Firm to respond to these requests within the statutory 30-day period.
- Deletion/return
- Upon termination of the Agreement, it deletes, destroys, or returns the personal data at the Firm's election, in accordance with the provisions of Article 8.
- Audit
- It makes available to the Firm the information and documents evidencing its compliance with the obligations under this Agreement; provided that reasonable prior written notice is given, that the workflow is not disrupted, and that confidentiality principles are observed, it permits audits to be conducted once a year, or in the event of a suspected data breach, by the Firm itself or by an independent auditor authorized by it.
5. Obligations of the Data Controller (the Firm)
- To fully fulfill the duty to inform the end-customers (KVKK Art. 10); this obligation rests solely with the Firm, and BotFront is only obliged to provide information about the third-party/recipient group to which data is transferred.
- To establish, and where necessary document, the legal grounds required for the processing of personal data (explicit consent or the other legal grounds set out in KVKK Art. 5 and Art. 6).
- To transfer data to BotFront only within the categories defined in this Agreement and limited to the specified purposes; and to communicate all of its instructions in a written and documented form.
- Where it is obliged to do so under the legislation, to fulfill its own VERBİS (Data Controllers' Registry) registration and notification obligations.
6. Transfer of Personal Data Abroad and Safeguards
In order to ensure the quality and continuity of the service, BotFront uses the technical infrastructures of certain sub-processors located abroad (Article 7). Accordingly, the end-customers' personal data may be transferred abroad. Such transfers are carried out in accordance with the graduated transfer regime introduced by the 2024 amendment to KVKK Art. 9:
- A direct transfer may be made to countries in respect of which the Personal Data Protection Board has issued an adequacy decision.
- Where there is no adequacy decision, one of the appropriate safeguards envisaged in the Law (in particular the 2024 standard contract or undertaking) is relied upon; the necessary notifications are made to the Board within 5 (five) business days following the signing of the standard contract.
- For continuous SaaS (software) transfers, explicit consent shall not be used on its own as a transfer mechanism; except in incidental (exceptional) cases, the existence of one of the appropriate safeguard conditions shall be required.
botcu is obliged to establish the necessary standard contracts, undertakings, and contractual safeguards relating to the transfer of data abroad with the sub-processors from which it receives services; whereas the Firm, within the scope of its own data-controller capacity, is obliged to complete the necessary notification, information, and documentation processes.
7. Sub-Processors and the Approval Process
In order for the service to be provided in full, the Firm consents to BotFront's use of the sub-processors specified below. Because some of these providers are headquartered or have servers located abroad, the relevant transfers are subject to the safeguards set out in Article 6:
- Anthropic (Claude LLM) — USA
- Message text is transferred for processing for the purposes of intent classification and artificial intelligence analysis. A transfer abroad takes place in this context.
- Google Firebase / Google Cloud — USA/EU
- Used for the control plane (configuration/authorization) and hosting services (the agent runtime on GCP virtual machines). A transfer abroad may take place in this context.
- Vercel — USA
- Used for hosting services for the management panel (dashboard). A transfer abroad takes place in this context.
- Meta / WhatsApp Business API
- The transmission (carriage) channel for messages. All message traffic flows through this infrastructure.
- Polar
- The billing and subscription management infrastructure. This service covers only the Firm's own billing and subscription data; the end-customers' message content is not transferred to this channel.
When BotFront plans to add a new sub-processor or to change an existing one, it informs the Firm with reasonable prior notice. The Firm may object to such a change where justified grounds exist. In the event of an objection, the parties endeavor to agree on a reasonable solution; if agreement cannot be reached, the Firm has the right to terminate the service agreement. BotFront acknowledges and undertakes that it will impose on each sub-processor data protection obligations equivalent to those arising from this Agreement, and that the sub-processors will be directly liable to the Firm for their data breaches.
8. Termination of the Agreement and Deletion or Return of Personal Data
Upon termination of this Agreement or of the main service relationship between the parties for any reason, BotFront shall, at the Firm's election, delete, destroy, or return to the Firm the end-customers' personal data within a reasonable period, destroying all existing copies. Data that must be retained under the legislation shall be kept for the duration of the statutory retention periods, solely for the purpose of fulfilling this obligation and with restricted access.
Because the stock ledger structure is append-only in nature, deletion is performed by entirely purging the records belonging to the relevant tenant from the database as a whole; no retroactive update (UPDATE) operation is performed on individual records.
9. Miscellaneous Provisions
- This Agreement constitutes an integral annex to the main service/subscription agreement between the parties. In the event of a conflict between the two agreements, the provisions of this Agreement shall prevail with respect to matters concerning the protection of personal data.
- The provisions of Law No. 6698 (KVKK) and the relevant secondary legislation shall govern the interpretation, application, and resolution of disputes under this Agreement.
- For communications and notifications: https://botfront.com.tr • contact@lumiostudio.co.